<html>
<body>

<?php include 'mainheader.php'; ?>

<?php

// Useful functions
function insertAsset( $assetName, $month, $year, $assetValue )
{
	$con = mysqli_connect("localhost", "root", "assetsdbpass", "assetsdb");

	if( mysqli_connect_errno($con) )
	{
		echo "Fail to connect to MySQL: " . mysqli_connect_error();
	}

	$sql = "INSERT INTO assets(name, month, year, value) VALUES('" . $assetName . "', '" . $month . "', '" . $year . "', '" . $assetValue . "')";

	if( !mysqli_query($con, $sql) )
	{
		echo "<h2>Assets NOT inserted!!!</h2>";
		die('Error: ' . mysqli_erros($con));
	}

	mysqli_close($con);
}

function showAssetsForm()
{
	// Inicio do conteudo da add
	echo "<h4>Please, enter assets values:</h4>";

	echo "<form name='input' action='add.php' method='get'>";
	echo "Month: <input type='text' name='month'>";
	echo "Year: <input type='text' name='year'><br><br>";
	echo "2Qtos Campo Grande: <input type='text' name='cg'><br>";
	echo "2Qtos Curicica: <input type='text' name='cu'><br>";
	echo "Gold: <input type='text' name='g'><br>";
	echo "Silver: <input type='text' name='s'><br>";
	echo "Dow: <input type='text' name='do'><br>";
	echo "iBovespa: <input type='text' name='b'><br>";
	echo "PETR4: <input type='text' name='p'><br>";
	echo "VALE5: <input type='text' name='v'><br>";
	echo "OGXP3: <input type='text' name='o'><br>";
	echo "USIM5: <input type='text' name='u'><br>";
	echo "Dollar: <input type='text' name='dr'><br>";
	echo "Euro: <input type='text' name='er'><br>";
	echo "<br>";
	echo "<input type='submit' value='Submit'>";
	echo "</form>";
}

if( !isset($_GET["month"]) || !isset($_GET["year"]) ||
    !isset($_GET["cg"])    || !isset($_GET["cu"])   || !isset($_GET["g"]) || !isset($_GET["s"]) || !isset($_GET["do"]) || !isset($_GET["b"]) ||
    !isset($_GET["p"])     || !isset($_GET["v"])    || !isset($_GET["o"]) || !isset($_GET["u"]) || !isset($_GET["dr"]) || !isset($_GET["er"]) )
{
	showAssetsForm();
	return;
}
else
{

	if( (!is_numeric($_GET["month"]) ) || (!is_numeric($_GET["year"] ) ) || (!is_numeric($_GET["cg"] ) ) || (!is_numeric($_GET["cu"] ) ) ||
	    (!is_numeric($_GET["g"] ) ) || (!is_numeric($_GET["s"] ) ) || (!is_numeric($_GET["do"] ) ) || (!is_numeric($_GET["b"] ) ) ||
	    (!is_numeric($_GET["p"] ) ) || (!is_numeric($_GET["v"] ) ) || (!is_numeric($_GET["o"] ) ) || (!is_numeric($_GET["u"] ) ) ||
	    (!is_numeric($_GET["dr"] ) ) || (!is_numeric($_GET["er"] ) ))
	{
		showAssetsForm();
		return;
	}
}

// Valid data.

// Insert on database
insertAsset( "2Qtos C. Grande", $_GET["month"], $_GET["year"], $_GET["cg"] );
insertAsset( "2Qtos Curicica",  $_GET["month"], $_GET["year"], $_GET["cu"] );
insertAsset( "GOLD", $_GET["month"], $_GET["year"], $_GET["g"] );
insertAsset( "SILVER", $_GET["month"], $_GET["year"], $_GET["s"] );
insertAsset( "DOW", $_GET["month"], $_GET["year"], $_GET["do"] );
insertAsset( "iBovespa", $_GET["month"], $_GET["year"], $_GET["b"]);
insertAsset( "PETR4", $_GET["month"], $_GET["year"], $_GET["p"]);
insertAsset( "VALE5", $_GET["month"], $_GET["year"], $_GET["v"]);
insertAsset( "OGXP3", $_GET["month"], $_GET["year"], $_GET["o"]);
insertAsset( "USIM5", $_GET["month"], $_GET["year"], $_GET["u"]);
insertAsset( "Dollar", $_GET["month"], $_GET["year"], $_GET["dr"]);
insertAsset( "Euro", $_GET["month"], $_GET["year"], $_GET["er"]);

echo "<h2>Assets inserted!!!</h2>";

?>

</body>
</html>
